Skip to content

MAB-726: Prevent User to change their own assigned country#126

Open
Joselgc1 wants to merge 1 commit intounesco-mabfrom
MAB-726
Open

MAB-726: Prevent User to change their own assigned country#126
Joselgc1 wants to merge 1 commit intounesco-mabfrom
MAB-726

Conversation

@Joselgc1
Copy link

Description

The issue was that users could go into their own profile and change their assigned country, which then gave them access to BRs for that country, even though that assignment should only be managed by the MAB Secretariat. Fixed it mainly on the backend by updating the editUserProfile mutation so the country attribute is ignored unless the request is for another user and the person making the change has the can_see_users permission.

Useful links

Type of change

Please delete options that are not relevant.

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Improvement (refactor or addition to existing functionality)

Checklist:

( * == Mandatory )

  • * I have set myself as assignee of the pull request
  • * My code follows the style guidelines of this project
  • * Linting does not generate new warnings
  • * I have performed a self-review of my own code
  • * I have put the ticket for review, adding the oort-frontend team to the list of reviewers
  • * I have commented my code, particularly in hard-to-understand areas
  • * I have put JSDoc comment in all required places
  • * My changes generate no new warnings
  • * I have included screenshots describing my changes if relevant
  • * I have selected labels in the Pull Request, according to the changes with code brings
  • I have made corresponding changes to the documentation ( if required )
  • I have added tests that prove my fix is effective or that my feature works
  • New and existing unit tests pass locally with my changes
  • Any dependent changes have been merged and published in downstream modules

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant